Vulnerabilities exploitable today
378,183in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,717
New KEV · 24H1
Exploit Today ≥ 701,649
Distribution · last window
- Critical2,332
- High8,494
- Medium6,769
- Low765
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-23663—32.3%
——10——CVE-2025-63464—32.3%
——10——CVE-2025-23879—32.3%
——10——CVE-2025-63469—32.3%
——10——CVE-2025-23716—32.3%
——10——CVE-2025-1919—32.3%
——10——CVE-2024-34519—32.3%
——10——CVE-2025-47202—32.3%
——10——CVE-2021-4256—32.3%
——10——CVE-2025-25083—32.3%
——10——CVE-2019-1628—32.3%
——10——CVE-2025-23635—32.3%
——10——CVE-2025-25169—32.3%
——10——CVE-2026-93366.5 MED32.3%
——10IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to a denial of service, caused by sending a specially-crafted HTTP request to an administrative endpoint. A remote attacker could exploit this vulnerability to cause the server to exhaust filesystem space.5dCVE-2025-63467—32.3%
——10——CVE-2020-2913—32.3%
——10——CVE-1999-0143—32.3%
——10——CVE-2025-23739—32.3%
——10——CVE-2025-25102—32.3%
——10——CVE-2025-23740—32.3%
——10——CVE-2026-126206.5 MED32.3%
——10The GridTime 3000 GNSS Time Server leaks the access token in the URL parameters of some endpoints.
This issue affects GridTime 3000: from 1.0r0.03 through 1.1r0.0.74dCVE-2026-862877.5 HIG32.3%
——10Net::IP::LPM versions before 1.12 for Perl accept malformed prefix lengths.
Non-numeric and non-ASCII prefix lengths are accepted and treated as 0. Integers over 31 bits are silently truncated. A single malformed mask will poison the lookup table.
The result is that the lookup will silently succeed for every address. An allow-list will allow every address, and a deny-list will block every address.13dCVE-1999-0501—32.3%
——10——CVE-2026-277902.7 LOW32.3%
——10Uncaught Exception (CWE-248) in the T20 Readers allows an authenticated and authorized operator to trigger a restart by sending specific requests, resulting in a temporary denial of service. Version of Command Centre affected:
* 9.50 prior to vCR9.50.260616a (distributed in 9.50.1587(MR1))
* 9.40 prior to vCR9.40.260616a (distributed in 9.40.3130(MR3))
* 9.30 prior to vCR9.30.260616a (distributed in 9.30.3983(MR5))
* 9.20 prior to vCR9.20.260616a (distributed in 9.20.4349(MR7))
* all versions of 9.10 and prior.38dCVE-2024-3994—32.3%
——10——CVE-2025-44764.3 MED32.3%
——10A denial-of-service vulnerability has been identified in the libsoup HTTP client library. This flaw can be triggered when a libsoup client receives a 401 (Unauthorized) HTTP response containing a specifically crafted domain parameter within the WWW-Authenticate header. Processing this malformed header can lead to a crash of the client application using libsoup. An attacker could exploit this by setting up a malicious HTTP server. If a user's application using the vulnerable libsoup library connects to this malicious server, it could result in a denial-of-service. Successful exploitation requires tricking a user's client application into connecting to the attacker's malicious server.83dCVE-2025-25035—32.3%
——10——CVE-2025-8061—32.3%
——10——CVE-2024-57373—32.3%
——10——CVE-2021-4409—32.3%
——10——CVE-2017-12164—32.3%
——10——CVE-2024-23841—32.3%
——10——CVE-2025-31524—32.3%
——10——CVE-2024-1682—32.3%
——10——CVE-2024-25841—32.3%
——10——CVE-2025-7121—32.3%
——10——CVE-2025-7188—32.3%
——10——CVE-2026-0842—32.3%
——10——CVE-2021-4415—32.3%
——10——CVE-2024-6465—32.3%
——10——